Re: relayd blocking by IP

2022-05-29 Thread Marcus MERIGHI
fosf...@gmail.com (Fabio Martins), 2022.05.06 (Fri) 00:43 (CEST): > On Thursday, May 5, 2022, Stuart Henderson > wrote: > > not quite, PF is looking up the IP in the table to decide which port > > number to use > > then the different port number is handled in relayd to pick between > > two context

Re: relayd blocking by IP

2022-05-05 Thread Fabio Martins
On Thursday, May 5, 2022, Stuart Henderson wrote: > > > not quite, PF is looking up the IP in the table to decide which port > number to use > > then the different port number is handled in relayd to pick between > two contexts: > > one does not inspect Host (for those requests coming from > addr

Re: relayd blocking by IP

2022-05-05 Thread Stuart Henderson
On 2022-05-05, Fabio Martins wrote: > On Thursday, May 5, 2022, Marcus MERIGHI wrote: > >> Hello Stuart, Hello Fabio, >> >> thanks for reading and suggesting! >> >> >> Exactly, though it is going to be relayd that is listening and >> forwarding to the application (or not, in case of geoblocking).

Re: relayd blocking by IP

2022-05-05 Thread Fabio Martins
On Thursday, May 5, 2022, Marcus MERIGHI wrote: > Hello Stuart, Hello Fabio, > > thanks for reading and suggesting! > > > Exactly, though it is going to be relayd that is listening and > forwarding to the application (or not, in case of geoblocking). > > Marcus > This way you are only blocking p

Re: relayd blocking by IP

2022-05-05 Thread Marcus MERIGHI
Hello Stuart, Hello Fabio, thanks for reading and suggesting! fosf...@gmail.com (Fabio Martins), 2022.05.04 (Wed) 22:29 (CEST): > On Wednesday, May 4, 2022, Stuart Henderson > wrote: > > On 2022-05-04, Marcus MERIGHI wrote: > > > I need to block http/s traffic, but only for some Host: header va

Re: relayd blocking by IP

2022-05-04 Thread Fabio Martins
On Wednesday, May 4, 2022, Stuart Henderson wrote: > On 2022-05-04, Marcus MERIGHI wrote: > > Hello! > > > > I need to block http/s traffic, but only for some Host: header values. > > I.e. domain "xyz.abc" should be reachable, domain "klm.opq" not, both > > behind the same IP. > > > > This rules

Re: relayd blocking by IP

2022-05-04 Thread Stuart Henderson
On 2022-05-04, Marcus MERIGHI wrote: > Hello! > > I need to block http/s traffic, but only for some Host: header values. > I.e. domain "xyz.abc" should be reachable, domain "klm.opq" not, both > behind the same IP. > > This rules out blocking with PF. > > I looked at relayd(8)/relayd.conf(5) next